What is the “Services” Windows forensic artifact?

The Windows service configuration database, stored in the SYSTEM registry hive, is the authoritative inventory of every service and driver registered on a machine. Each entry records the binary’s full path, its start type (automatic, manual, or disabled), the account it runs under, and its load behavior. Because services start with the operating system and typically execute with elevated privileges, installing persistence as a service is one of the oldest and most reliable techniques in an attacker’s playbook — and every such installation leaves a durable mark in this hive.

For a DFIR investigator, the Services artifact answers a question that process lists cannot: not what is running now, but what is configured to run — including entries whose binaries have since been deleted to cover tracks. Unsigned services, binaries in user-writable or temporary paths, system-like display names mimicking legitimate Windows components, and services registered outside any software deployment or patch window are all high-fidelity indicators that surface immediately when this database is analyzed at scale.


Enterprise Forensic Applications

Service configuration analysis is a cornerstone of persistence hunting. During Proactive Compromise Assessments, TensorGuard audits service registrations across the fleet to expose persistence mechanisms that real-time tools accepted as background noise — unauthorized remote access tools registered as system services, masqueraded binaries, and drivers installed during a compromise and never removed. Correlated with $MFT, ShimCache, and event logs, a single suspicious service entry often becomes the thread that unravels an entire intrusion.


Collecting, Decoding, and Viewing “Services” with TensorGuard

  1. Create a TensorGuard account and sign in to the TensorGuard console at https://app.tensorguard.com.
  2. Select “Case Manager”, then the plus button to create a case. This will contain your enrolled devices, their reports, and any manually submitted collections.
  3. Linked inside the case menu, download the TensorGuard Forensic Collector and run it on your target system.
  4. In the console, click the plus button for “New Enrollment”, copy the enrollment key, and paste it into the TensorGuard Forensic Collector on your target device.
  5. Now that you have a device enrolled, select the device(s), and click “Send Signal”. Answer the questions regarding what you want to look for in the analysis, any alerting on positive findings, and if the collection and analysis should be recurring.
  6. Once the report is generated, you’ll have Services delivered in the browser, alongside an executive summary and timeline of findings.

Get Started

TensorGuard™ is a trademark of TensorGuard Inc. All other trademarks are the property of their respective owners. The information provided on this website is for educational and informational purposes only and does not constitute legal, forensic, or professional advice. Due to the complexities of Digital Forensics and potential legal implications, you should always consult with qualified legal counsel or a certified digital forensics expert before taking action based on findings.

Services Forensic Integration Logo

Services

Windows

The complete service and driver configuration database — binary paths, start types, and run-as accounts — where attackers hide persistence that starts with the OS.

Start with a Compromise Assessment.

One flat fee, fully credited toward a subscription. We conduct a complete, AI-driven Compromise Assessment across your critical systems — with evidence-linked findings your team can validate in minutes.

TensorGuard Automated DFIR Platform Dashboard